^

Standards Compliance

Standards Compliance

DO-326B/ED-202A Trusted Aerospace Cybersecurity Framework Guide

Security has become a primary challenge for the aviation industry in aerospace system development and certification. Both the aviation network and aircraft are increasingly connected to the internet (nose-to-tail) and other private networks. The connected services may include weather forecasts, maintenance data, and high-speed broadband in the cabin as in-flight entertainment (IFE).

The Aircraft Communication Addressing and Reporting System (ACARS) has traditionally utilized a digital datalink system for transmission of short messages between aircraft and ground stations via air band radio or satellite. ACARS is now integrating Internet Protocol (IP), database upload, and many other technologies.

This technological evolution has clear and undoubted benefits. But the increased connectivity coupled with the use of standard communications protocols has clear implications for security – and hence, aircraft safety.

What is the Aerospace Security Framework?

Avionics development has not historically been concerned with security in mind, and so software upgrades for security requirements on the post facto certification baselines are either costly or ineffective.

The challenge is to establish a common Aerospace Security Framework underpinned by most appropriate best-practice guidelines to form a robust and secure ecosystem that will ensure aeronautical systems safety. For example, DO-326B/ED-202A guidelines from RTCA would be most appropriate for the development of a Line Replaceable Unit (LRU), whereas ISO 27000 and NIST standards would be more appropriate for the supporting Information Technology (IT) infrastructure.

What are RTCA DO-326B and EUROCAE ED-202A?

The international standards DO-326B (USA) and ED-202A (Europe) are both entitled “Airworthiness Security Process Specification” and were developed in tandem. In 2019, they became the sole Acceptable Means of Compliance (AMC) for FAA and EASA cybersecurity airworthiness certification, with their certification processes representing top-level guidance.

The “DO-326/ED-202 set” also includes the following companion documents to expand on that overview.

  • DO-356A/ED-203A: “Airworthiness Security Methods and Considerations”
  • DO-355/ED-204: “Information Security Guidance for Continuing Airworthiness”
  • ED-201A: “Aeronautical Information System Security Framework Guidance”
  • ED-205: “Process Standard for Security Certification and Declaration of ATM ANS Ground Systems”

What is the Airworthy Security Process?

In general, the DO-326/ED-202 set is conceptually similar to DO-178C. It defers to DO-178C where there are parallels, so that the primary focuses are the AirWorthiness Security Process (AWSP), Security Risk Assessment Process (SRAP), and the Security Development Process (SDP).

The purpose of the Airworthiness Security Process is to ensure that when there is an unauthorized interaction, the aircraft will always remain in a condition for safe operation. The goal is to establish the security risk to the aircraft and its systems is acceptable (as analysed by the AWSP).

What are RTCA DO-355 and EUROCAE ED-204A?

RTCA DO-355/ED-204A “Information Security Guidance for Continued Airworthiness” offers guidance for multiple phases within the product life cycle, It encompasses operation, support, maintenance, administration, and decommissioning.

Type Certification activities linked to the operation and maintenance of aircraft are introduced in ED-202A/DO-326B and expanded upon in ED204A/DO355A.

RTCA DO-355/ED-204A exclusively addresses information security risks. The measures to counter these risks extend beyond solely technical safeguards and may also involve operational or managerial security measures.

What are RTCA DO-356A and EUROCAE ED-203A?

DO-356A/ED-203A “Airworthiness Security Methods and Considerations” is supplemental to DO-326B/ED-202A. It details security objectives that are to be met at each stage of development, along with airworthiness risk assessment and certification processes processes and the evidential artefacts required.

DO-356A/ED-203A contains detailed information on the risk assessment of cybersecurity threats relating to the aircraft level of development, and introduces security assurance levels. Security architecture principles are detailed at aircraft level, system-level, and item level. An extensive appendix is supported by examples and includes details of security assurance objectives and security assurance guidance.

DO-326B/ED-202A and DO-356A/ED-203A documents are mutually dependent, with the former describing the activities to be undertaken and the latter presenting associated guidance information for those activities. An appendix in DO-356A and ED-203A maps activities to guidance between these standards.

What are Security Assurance Levels?

DO-356A/ED-203A introduces the concept of Security Assurance Levels from 0-3, with 3 being the most critical and hence most demanding. The airworthy security process exposes details of the Airworthiness Security Process activities, their interfaces and artifacts, and the dependencies between those activities. A plan is required to show how each of these activities will be implemented. An appendix to DO-326B/ED-202A describes the purpose, details, input and output, and compliance objectives for each plan.

An overview of security certification plans by severity of effect is shown below. Although nominally analogous to DO-178C DAL categorisation, this is a higher level assignment — not at the level of objectives. Plans that are categorized “as negotiated” are to be agreed on a case-by-case basis with the certification authority.

What other guidance is associated with DO-326B/ED 202A and DO-356A/ED-203A?

DO-326B/ED-202A, DO-356A/ED-203A, and DO-178C/ED-12C

Aeronautical systems security is inextricably intertwined with aircraft safety DO-178C (along with its European counterpart, ED-12C) is the latest version of a long-established standard that defines the process to be used in the development of software for use in airborne systems. As aircraft systems and their associated software become ever more complex, the list of supplemental documents has grown in tandem. DO‑326B/ED-202A (and hence DO-356A/ED-203A) are examples of such documents – and so their guidance must be applied in that context.

DO-326B/ED-202A, DO-356A/ED-203A, and DO-355/ED-204

Like DO-356A/ED-203A, DO-355/ED-204, “Information Security Guidance for Continuing Airworthi­ness” is supplemental to DO‑326B/ED-202A. It details guidance associated with information-related security risks. It is applicable when the aircraft is in service – that is, during operations and maintenance – and it includes technical security, operational, and management security measures.

DO-326B/ED-202A, DO-356A/ED-203A, and ED-201A

ED-201A, “Aeronautical Information System Security Framework Guidance” is a high-level document. It details the shared responsibility for Aeronautical Information System Security (AISS), identifying and describing the pertinent areas of concern to be considered across stakeholders.

DO-326B/ED-202A, DO-356A/ED-203A, and ED-205

ED-205, “Process Standard for Security Certification and Declaration of Air Traffic Management/Air Navigation Services (ATM/ANS) Ground Systems” is concerned with the extent to which the ATM/ANS ground systems are appropriately secure for use. The process it describes can be used to identify, evaluate, and manage the potential impact of security breaches.

DO-326B/ED-202A and DO-356A/ED-203A: Security assessment and development

Applicants seeking to develop a system compliant with the DO-326/ED-202 set are required to follow the illustrated process:

Some of the key phases in this process are outlined below.

The security assessment and development phase involves the definition and documentation of the intended functions of the system, to include customer-facing features, and maintenance/support functions. Increased connectivity in airplane system functionality may introduce new risks associated with security vulnerabilities, because Aerospace Recommended Practice ARP 4761 and similar safety guidelines do not consider deliberate unauthorized electronic interactions through exploitation/attack. An initial assessment is also required to discover the security aspects of the interfacing system.

DO-326B/ED-202A and DO-356A/ED 203A: Connectivity to external devices or networks

It is necessary to determine whether any elements of the system are connected to external devices or networks.  For each such connection, there needs to be consideration of whether the external device is trusted or non-trusted, authentication methods, data sharing mechanisms, access mechanisms, and protection mechanisms.

DO-326B/ED-202A and DO-356A/ED 203A: Create the data flow diagram(s)

These data flow diagram(s) describe the communication between the components of the systems and components to external systems (networks/devices). The data flow diagram(s) should include both physical and logical flows.

DO-326B/ED-202A and DO 356A/ED 203A: Evaluate connectivity impact to safety, and develop mitigations

Threat modelling is a structured approach to identifying and prioritizing potential threats to a system and determining the value that potential mitigations would have in reducing or neutralizing those threats. It defines threats and their mitigation in terms of assets, attackers, vulnerabilities access vectors, threat conditions, threat scenarios, and security measures.

Threat conditions reflect the potential impact on the function under evaluation. This may include considerations of the loss of integrity, availability, or confidentiality associated with a function manifesting into a misleading or malfunctioning condition. Threat conditions may include failures that only have a safety effect in combination which might therefore be overlooked in the function-by-function, top-down deductive qualitative examination of Functional Hazard Analysis (FHA), or the similarly granular bottom-up process deployed during System Safety Assessment (SSA).

The risk associated with each threat depends on the likelihood of occurrence, impact (severity), and remediation cost. The sophistication of the mitigation mechanism to be developed depends on the overall risk factor/score.

DO-326B/ED-202A and DO-356A/ED 203A: Conducting a security assessment

Security threats identified in prior phases of the process are now evaluated. A popular threat assessment methodology is “DREAD” (Damage, Reproducibility, Exploitability, Affected Users and Discoverability). The probability of occurrence(P), Impact (I) and the risk are defined as (R+E+DI), (D+A) and (P x I) respectively.

The threats are then prioritized according to risk score, and proportionate actions (mitigations) are developed for each. These mitigations then need to be accounted for in the requirements process, verified, and validated.

The security assessment is then performed, during which the identified mitigations are reviewed against security, safety requirements and identified failures from the Functional Hazard Analysis.

Validation & verification of security architecture, design, and implementation

The following verification and validation techniques are used to ensure that the mitigations are effective, many of which are underpinned by the LDRA tool suite as described here.

  • security requirements testing
  • threat mitigation testing
  • abuse case testing
  • static code analysis
  • attack surface analysis
  • known vulnerability scanning
  • software composition analysis
  • penetration testing

DO-326B/ED-202A and DO-356A/ED 203A: The security development and risk assessment process V-model

The DO-326/ED-202 set provides a holistic life cycle approach for aerospace security. This encompasses the planning stage, impact analysis, security risk assessment, security architecture design, security component implementation, validation/verification of security requirements, and security considerations for continuing airworthiness. It also provides a unified collaboration of system, safety, and security processes, activities, and lifecycle products.

From security assessment, the threats, threat scenarios, and severity are analysed for impact on failure/hazard conditions. Security architecture, design, and requirements are also coordinated with system development. Security implementation should not be attempted retrospectively once system development is completed. The unified lifecycle approach calls for greater collaboration with multiple stakeholders from the safety, system, and security processes.

The diagram below illustrates how a security development life cycle can be represented in a V model-like requirement-based, safety-critical system/software development lifecycle.

The top guiding document is a security compliance plan. This has much in common with any other system/software certification plan, except that its focus is entirely on the security layers within a defence-in-depth strategy (including embedded, system-level and network-level layers). The security environment encompasses the surrounding external/internal environment of the system under consideration.

Threats, vulnerabilities, and the probability of threat realization (leading to exploitation) are then assessed. Each potential exploitation is considered for its potential impact on functionality and safety, and an initial risk assessment is carried out to understand the potential impact of an attack or exploitation.

The mitigation methods or countermeasures are designed to thwart a possible attack or reduce the impact to an acceptable level. Once the security architecture and design are implemented, the verification process leverages multiple verification techniques are employed to ensure that the mitigation/measures are effective against an attack.

How does LDRA help with compliance?

Support for validation and verification in compliance with DO-326B/ED-202A and DO-356A/ED-203A

The following verification and validation techniques are used to ensure that the mitigations are effective, many of which are underpinned by the LDRA tool suite as described below:

  • Security requirements testing
    • Automated by the TBmanager component of the LDRA tool suite
  • Taint analysis
    • Automated by the TBvision component of the LDRA tool suite
  • Threat mitigation testing
    • Supported by the TBrun component of the LDRA tool suite
  • Abuse case testing
    • Supported by the TBrun component of the LDRA tool suite
  • Static code analysis
    • Automated by the TBvision component of the LDRA tool suite
  • Attack surface analysis
  • Known vulnerability scanning
  • Software composition analysis
  • Penetration testing
    • Complemented by the TBextreme component of the LDRA tool suite

The DO-326B/ED-202A process V-model and DO-178C

The DO‑326B/ED-202A V-model demonstrates considerable synergy with that used to define DO-178C. Many of the software development processes, tools, and techniques used to demonstrate the correct implementation of safety-related requirements in application code are equally applicable here. Details can be found here describing how those facilities are provided in the LDRA tool suite and tuned to the appropriate Development Assurance Level (DAL).

DO-326B/ED-202A and DO-356A/ED-203A consultancy from LDRA Certification Services (LCS)

Aviation standards are demanding because of their sheer scope. They encompass systems (ARP 4754A/DO-297), safety (ARP 4761), security (DO-326B), software tool qualification (RTCA DO-330), software development (DO-178C) and programmable electronic hardware (RTCA DO‑254). Some of these standards are long standing. For example, DO-178 was first published in its original form way back in 1981. Many development teams in companies across the world therefore have a great deal of experience in meeting the challenges posed by its latest successor, DO-178C.

For development teams new to this established sector, the existence of competitors who are more accustomed to finding a path through the maze of complex acronyms, terminology and cross references make it even more important to get it right first time and achieve certification goals. Conversely, more established players can always benefit from an optimized path through that aviation standards maze to keep cost and time overheads to a minimum.

It is, of course, entirely possible to develop a compliant system or application with no outside assistance at all. But to do so in a fashion that ensures a product of optimal quality, safety and cost is often far easier with a little help.

Developing systems and software that can be certified and used for safety- and security- critical functions in today’s aircraft can be an extremely difficult task, with engineers constantly facing challenges related to cost, schedule, product safety, defects, regulations, and other similar factors. Although standards such as those in the DO-326/ED-202 set are logically structured and mandate recommended processes, they do not prescribe the characteristics and behaviour of the product.  Engaging LDRA Certification Services (LCS) to facilitate and reduce the cost of qualification and certification of systems and software is one way to mitigate those challenges.

Conclusions

The challenge for authorities across the world is to establish a common security framework underpinned by most appropriate best-practice guidelines to form a robust and secure ecosystem. In 2019, the international guidelines DO-326B/ED-202A entitled “Airworthiness Security Process Specification” became the sole Acceptable Means of Compliance for FAA and EASA cybersecurity airworthiness certification.

DO-356A/ED-203A “Airworthiness Security Methods and Considerations” is supplemental to DO-326B/ED-202A. It details security objectives that are to be met at each stage of development, along with airworthiness risk assessment and certification processes and the evidential artefacts required.

The DO-326/ED-202 set provides a holistic life cycle approach for aerospace security, encompassing the planning stage, impact analysis, security risk assessment, security architecture design, security component implementation, validation/verification of security requirements, and security considerations for continuing airworthiness.

Tackling the technicalities can be a daunting task for newcomers and experienced practitioners alike. LCS is engaged with multiple OEMs supporting their functional safety and cybersecurity goals, including compliance with the DO-326/ED-202 set. LCS also supports suppliers in various capacities ranging from training, gap analysis, process compliance, and other customized solutions.

Additional information

DO-326B/ED-202A PDFs – free download

DO-326B/ED-202A – further information

FREE 30 Day
TRIAL

Email Us

Email: info@ldra.com

Call Us

EMEA: +44 (0)151 649 9300

USA: +1 (855) 855 5372

INDIA: +91 80 4080 8707

Connect with LDRA